Initially reported as a "lucky" Arbitrum airdrop recipient, one crypto address appears to have actually scammed out over 600 different crypto wallets for more than 930,000 ARB tokens.
Blockchain intelligence firm Arkham confirmed with Decrypt that they too have identified that the address “belongs to a hacker who is sweeping funds from Arbitrum users.”
A closer look at the specific address's transactions reveals that it received 933,365 ARB tokens from a different Arbitrum address on March 24, a day after the layer-2 network’s highly-anticipated airdrop. ARB is the native governance token behind the layer-2 scaling solution for Ethereum called Arbitrum.
Transfer of 933,365 ARB tokens on-chain. Source: Arbiscan.
The source of those tokens is another contract whose creator is tagged as “Fake_Phishing18” on Arbitrum’s blockchain explorer.
Independent on-chain researcher 0xKnight also confirmed that he found victimreports of the hack. Users complained that their ARB tokens had been “auto-claimed” to the hacker's wallets.
Ethereum smart contract developer Brainsy signaled the malicious contract created by “Fake_Phishing18” on March 24 as well. They said that interacting with the contract creates an additional transaction request that appears as if it’s from the sender's wallet but instead is a phishing attack.
Watch out for this fake Arbitrum contract out there.
When I make a send the fake contract also makes a "transaction" that appears like its from my wallet. I assume to get me to interact with the contract. Stay safe out there. pic.twitter.com/ygGOddlTGU
MetaMask has warned against this sort of attack and termed it “address poisoning.”
It is an attempt where attackers poison the address list of users’ wallets by sending arbitrary transactions from addresses that closely resemble those with which the user has already interacted.
In this case, the attacker appears to have used both a phishing attack through a malicious smart contract and address poisoning, with Brainsy indicating that it makes the transaction look “like it's from [the users'] wallet.”
The image below shows that the “Fake_Phishing18” tagged account created the contract for the fake ARB tokens and then transferred ownership to “Fake_Phishing47.”
Contract details for fake ARB tokens. Source: Arbiscan
The same entity may have created a fake Aribtrum claiming site that if users interacted with the website, it would give the hacker control over the user’s wallets.
For instance, there was at least one identical webpage to the Arbitrum Foundation’s claim website circulating in some social media groups on the day of the airdrop.
The fake website claimed ARB tokens on the user’s behalf and transferred them to their wallets. The only subtle difference between them is that the original website has a countdown for when the claiming process will end.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.
Do you have the patience to wait 15 years before moving your crypto? One Bitcoin whale did, moving 50 BTC worth nearly $5 million that had previously sat untouched since July 2010.
The address, which starts with “04ba30,” received the 50 newly mined Bitcoin in 2010 when BTC was worth less than $0.10 per coin.
Now 15 years later, the whale—or a holder with a massive, valuable stash—performed its first transaction, sending out all 50 BTC worth $4.67 million at Bitcoin’s current price of $93,455....
CME Group on Thursday said it would introduce XRP futures on its derivatives marketplace for clients on May 19, the company announced Thursday.
The new product will allow clients to trade both a micro-sized contract of 2,500 XRP, and a larger-sized contract of 50,000 XRP.
"As innovation in the digital asset landscape continues to evolve, market participants continue to look to regulated derivatives products to manage risks across a wider range of tokens," Giovanni Vicioso, CME Group's global hea...
Institutional interest in Bitcoin intensified last month, even as retail investors reduced their exposure.
That’s the takeaway of John D’Agostino, head of strategy at Coinbase Institutional, who told CNBC Squawk Box that “pools of capital that have been buying during April” included “sovereign wealth funds, large institutional, long term duration pools of capital,” while Bitcoin exchange-traded funds (ETF) saw net outflows.
In April, D’Agostino said, “Bitcoin ETF flows were net negative to the...